Junglewise Threat Intelligence

CVE-2026-49831: DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.

CVE-2026-49831 · Severity: medium · CVSS 5.5 · Published 2026-09-02

Technologies: Dspace.

Executive brief

DSpace, an open-source platform for digital repositories, contains a vulnerability in its Curation Task feature. An attacker with administrative credentials can manipulate file output paths to overwrite critical system files or configuration settings. This could lead to a complete service outage or unauthorized changes to the platform's behavior.

Technical details

A path traversal vulnerability exists in the DSpace Curation Task Reporter due to insufficient validation of the output path parameter (-r). While originally a command-line tool, the feature is now accessible via the web UI to Collection, Community, and Site Administrators. An attacker with these administrative privileges can specify an arbitrary output path writable by the web server user (e.g., 'tomcat'). This can be used to overwrite configuration files in /dspace/config or binaries in /dspace/bin, potentially leading to Denial of Service (DoS) or further privilege escalation if combined with other vulnerabilities. The fix restricts output to configured directories and disables the reporter parameter for web-managed processes.

Affected products

  • DSpace DSpace <= 7.6.6, 8.0 <= 8.3, 9.0 <= 9.2, 10-rc1

Timeline

  • 2026-06-01: disclosed
  • 2026-07-08: advisory: GitHub Advisory published

References